As many as 250,000 credentials for Remote Desktop Protocol servers may have been offered for sale on the now-shuttered xDedic cybercrime marketplace. Security experts advise information security professionals to take several important steps that go far beyond simply changing credentials. The attackers will move laterally off the compromised system extremely quickly and try to establish multiple command-and-control channels as they know they will likely lose the initial access. In addition to closing RDP and SSH ports, organizations should also monitor for unusual behavior on their networks.”]
Source: https://www.databreachtoday.com/xdedic-what-to-do-if-your-rdp-server-was-pwned-a-9228

